Native VPN Payload Configuration For Android Work Managed Devices

Deploy native VPNs to Android Enterprise Work Managed devices using payloads. This feature eliminates reliance on third-party VPN solutions or VPN App Configurations to secure the network traffic on devices.

About this task

Use this procedure to create an Android Work Managed policy, configure a VPN payload and assign it to devices.

Procedure

Add a new profile:
  1. On the console, select main menu > Profiles. The Profiles page appears.
    Profiles page with new profile button highlighted
  2. Select New Profile in the top-right corner then select Android > Work Managed from the Add Profile dialog box.
    Select Android Work Managed from the Add Profile panel
    The Create Profile panel appears.
    Note: You can create profiles that have only configurations or only packages. You do not need to include both.
  3. On the General tab, enter a name and description for the profile. Note that the name and description are visible to the device user.
    Create Profile page with General tab selected
Add a new configuration for the VPN package:
  1. Select the Configurations tab then Add Configuration. The Add a Configuration panel appears.
    The Add a Configuration panel showing VPN selected
  2. From the Connectivity section, select VPN then a VPN payload type. A panel for the payload type appears.
    VPN Payload Configuration screen

    See Connectivity for descriptions of each available VPN type.

  3. Complete the information on the panel, including the VPN server hostname/IP address. Under Authentication, select Enrolled User Username.
  4. Select Save to return to the Create Profile page.
Assign the VPN package to devices:
  1. On the Configurations tab, select Add Configuration. The Add a Configuration panel appears.
  2. From the Security section, select Authentication.
    Select Authentication from the Security section of the Add Configuration panel
  3. On the Authentication panel, add a device administrator password then select Save.
    Authentication Panel
  4. On the Create Profile page, select Save and Assign. The Assign panel appears.
    Create Profile Configurations tab showing the new profile configuratons
  5. Select the device groups you want to assign the VPN payload to, then select Assign.
    Assign panel showing a device group selected

Results

Your new VPN payload get deployed to the devices you selected.